Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.1% | — | Zohocorp Zoho CRM Lead Magnet | 5/10/2021 | 17/6/2026 | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever… | |
| Modificada | Crítica (9.8) | 80% | — | Zohocorp Manageengine Opmanager | 30/9/2021 | 17/6/2026 | Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. | |
| Modificada | Alta (7.5) | 3.2% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key. | |
| Modificada | Alta (7.5) | 4.7% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. | |
| Modificada | Alta (7.5) | 4.7% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive. | |
| Modificada | Crítica (9.8) | 9.5% | — | Zohocorp Manageengine Admanager Plus | 27/9/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. | |
| Modificada | Crítica (9.8) | 93% | — | Zohocorp Manageengine Admanager Plus | 27/9/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | |
| Modificada | Crítica (9.8) | 2.2% | — | Zohocorp Manageengine Admanager Plus | 22/9/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. | |
| Modificada | Crítica (9.8) | 10% | — | Zohocorp Manageengine Admanager Plus | 22/9/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. | |
| Modificada | Alta (8.8) | 2.7% | — | Zohocorp Manageengine Admanager Plus | 21/9/2021 | 17/6/2026 | ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. | |
| Modificada | Crítica (9.8) | 4.8% | — | Zohocorp Manageengine Admanager Plus | 21/9/2021 | 17/6/2026 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. | |
| Modificada | Media (6.5) | 1.9% | — | Zohocorp Manageengine Admanager Plus | 21/9/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. | |
| Modificada | Alta (7.5) | 2.5% | — | Zohocorp Manageengine Admanager Plus | 21/9/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. | |
| Modificada | Crítica (9.8) | 3.4% | — | Zohocorp Manageengine Adselfservice Plus | 10/9/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | |
| Modificada | Crítica (9.8) | 2.8% | — | Zohocorp Manageengine Adselfservice Plus | 10/9/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. | |
| Modificada | Alta (7.5) | 5.5% | — | Zohocorp Manageengine Desktop Central | 10/9/2021 | 17/6/2026 | Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Adselfservice Plus | 7/9/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 1/9/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | |
| Modificada | Crítica (9.8) | 2.5% | — | Zohocorp Manageengine Adselfservice Plus | 30/8/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. | |
| Modificada | Crítica (9.8) | 4.8% | — | Zohocorp Manageengine Adselfservice Plus | 30/8/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Zohocorp Manageengine Adselfservice Plus | 30/8/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. | |
| Modificada | Crítica (9.8) | 18% | — | Zohocorp Manageengine Adselfservice Plus | 30/8/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. | |
| Modificada | Media (6.1) | 0.82% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. | |
| Modificada | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. | |
| Modificada | Media (6.1) | 0.82% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5225 allows stored XSS. |